This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Microsoft First view 2001-06-27
Product Word Last view 2003-04-11
Version 98 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software mac_os_x  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:microsoft:word

Activity : Overall

Related : CVE

  Date Alert Description
5 2003-04-11 CVE-2002-1143

Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."

4.6 2001-07-21 CVE-2001-0501

Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.

4.6 2001-06-27 CVE-2001-0240

Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.

Open Source Vulnerability Database (OSVDB)

id Description
10734 Microsoft Word/Excel Shared Document INCLUDEPICTURE Field Arbitrary File Read
10733 Microsoft Word/Excel Shared Document INCLUDETEXT Field Arbitrary File Read
1867 Microsoft Word Document Macro Execution
1837 Microsoft Word RTF Template Macro Execution